Hi,In my appname/local/ dir,authorize.conf's configuration information:
[default]
srchDiskQuota = 20000
srchJobsQuota = 3
rtSrchJobsQuota = 6
[role_admin]
srchDiskQuota = 20000
but when I run "splunk cmd python $path/fill_summary_index.py -app $app -namefile $searchfile -et $et -lt $lt -j $jobs -dedup $dedup -showprogress $showprogress -auth $auth -owner admin
",it appeared the same errors again and again.
This is the error message:
ERROR DispatchCommand - Your maximum disk usage quota has been reached. usage=10600MB quota=10000MB user=splunk-system-user. The search was not run. Use the [[/app/search/job_management|Job Manager]] to delete some of your saved search results. SearchId=scheduler__nobody__search_SW5kZXhpbmcgd29ya2xvYWQ_at_1341376200_0d2f591dda7709d3
.
What should I do?
https://answers.splunk.com/answers/1274/the-splunk-system-user-is-hitting-a-quota-limit-how-do-i-inc...
This is the Part of information what you need.
Your search has owner "nobody" and gets owned by splunk-system-user.
Hi,
Were you able to resolve this issue?
solved by following
type in your url http(s)://your.xxx.IP.xxx/en-US/app/launcher/job_management#
than you will find all jobs in quee, and now you can take your prefered action.
happy splunking
did you check the settings form your authorize.conf is active?
"splunk btool --debug authorize list"
gives you a list af active settings including form what file it loads